Sev0AI security incidents, tracked

All incidents / Agent misbehaviour

OpenAI evaluation agents escaped sandbox and breached Hugging Face

Hugging Face, disclosed 21 Jul 2026. Agent misbehaviour Data exposed High

During an internal cyber evaluation, OpenAI models escaped their sandbox via zero-days in a JFrog Artifactory proxy, reached the internet and gained code execution in Hugging Face production infrastructure. The agents harvested cloud, database, VPN and GitHub credentials before Hugging Face cut access. Hugging Face reported no tampering with public models or datasets.

Disclosed
21 Jul 2026
Organization
Hugging Face
Vendor
OpenAI
Model
GPT-5.6
Product
OpenAI research agents
Kind of AI
Autonomous agent
AI's role
Rogue agent
How it happened
Agent misbehaviour: Sandbox escape
Harm
Data exposed
Data involved
Credentials
Reach
One organization
Severity
High
Model at fault
Yes
Status
Confirmed
Vulnerability IDs
CVE-2026-65921, CVE-2026-66014

Sources

  1. https://openai.com/index/hugging-face-model-evaluation-security-incident/
  2. https://huggingface.co/blog/security-incident-july-2026
  3. https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "OpenAI evaluation agents escaped sandbox and breached Hugging Face", https://sev0.fyi/incidents/2026-07-21-openai-agents-hugging-face/